AI

DHS AI Rules

DHS AI policy explained: the 2024 framework, roadmap, 2025 GenAI playbook, and 2026 executive order every operator needs to align with now.
DHS AI Rules diagram summarizing the Safety and Security Framework, Roadmap, GenAI Playbook, and 2026 Executive Order

Introduction

The DHS AI Rules were originally unveiled as the Homeland Security Unveils New AI Guidelines package, and have grown into a layered governance stack shaping roughly 160 federal AI systems. The Department of Homeland Security published its Safety and Security Framework for AI in Critical Infrastructure on 26 April 2024. In March 2024 the agency also released the first DHS AI Roadmap which set three cross-cutting priorities for mission AI. On 7 January 2025 DHS added a GenAI Playbook for public-sector deployment filling in operational detail the roadmap left open. In June 2026 President Trump signed a new Executive Order on Promoting Advanced AI Innovation and Security rewiring federal AI priorities around speed and red teaming. These four instruments together are what practitioners now mean when they talk about the federal AI rules on homeland security use of AI.

Quick Answers on the framework

What exactly are the federal AI rules in one plain sentence that a security leader can quote?

The DHS guidance are a layered governance stack covering a 2024 Safety and Security Framework, a mission-focused AI Roadmap, a 2025 GenAI Playbook, and the 2026 federal AI Executive Order.

Who in federal civilian government and private sector must actually follow the federal AI rules?

The DHS guidance apply to federal civilian agencies, the 16 designated critical infrastructure sectors, and vendors selling AI systems to DHS components, with contractors bound through procurement language.

How are the federal AI rules actually enforced across federal agencies and private vendors today?

The federal AI rules are enforced through OMB oversight, inspector general audits, DHS Office for Civil Rights review, and procurement penalties for vendor noncompliance.

Key Takeaways on the federal AI rules

  • The federal AI guidance are a stack of four instruments, not one document, and operators must align with all four.
  • The April 2024 Safety and Security Framework sets five role-based pillars for critical infrastructure owners.
  • The 2026 Executive Order replaced EO 14110 and loosened some reporting rules while keeping red-team obligations.
  • DHS maintains a public use-case inventory listing roughly 160 AI systems, with law enforcement as the largest category.

Table of contents

Understanding the DHS framework in Plain Terms

The DHS AI rules are a layered federal governance stack covering critical infrastructure safety, mission-focused AI use, generative AI adoption, and executive-order direction, applied to agencies, operators, and vendors.

Interactive readiness scorer

Score Your DHS AI rules Readiness

Rate your organization’s current maturity across the five pillars of the DHS Safety and Security Framework. The scorer returns a readiness index and highlights the pillar most likely to delay compliance.

Score: 3 / 5

NoneMature

Score: 2 / 5

NoneMature

Score: 2 / 5

NoneMature

Score: 1 / 5

NoneMature

Score: 2 / 5

NoneMature

Electricity

Pick oneMultiple ok

Your readiness index

40

Developing

Weakest pillar: Civil Society Engagement. Priority next quarter.

  • Cloud: 60%
  • Developer: 40%
  • Operator: 40%
  • Civil: 20%
  • Public: 40%

Source: DHS Safety and Security Framework for AI in Critical Infrastructure, April 2024.

What the DHS AI Rules Actually Cover

The DHS AI direction cover four distinct instruments that together form a federal AI governance stack. The 2024 Safety and Security Framework targets critical infrastructure owners, cloud providers, model developers, and civil society in equal measure. The 2024 DHS AI Roadmap sets internal mission priorities for how DHS components use AI inside their programs. The 2025 GenAI Playbook translates principles into step-by-step adoption guidance for public-sector teams. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

Each instrument answers a different question that an operator needs to resolve before deploying an AI system. The framework answers who is responsible for what along the AI supply chain, with five role-based pillars. The roadmap answers what missions DHS will prioritize, including cyber defense, immigration, counter-trafficking, and disaster response. The playbook answers how a public-sector team should pilot, scale, or retire a generative AI tool. The 2026 Executive Order then answers which rules carry over from the earlier Biden-era order and which have been replaced or paused.

Readers often conflate the four instruments because the press releases overlapped and the acronyms sound similar. The framework is public, voluntary for private operators, and sits alongside the broader responsible AI governance frameworks that enterprise teams already use. The playbook is a how-to manual for federal teams and reads much like an internal product guide. The roadmap and the executive order are strategy documents that reset priorities every one to two years. Reading them in order shows a clear policy arc from principles to practice to procurement.

Why Homeland Security Issued New AI Rules

Building on that foundation, the question becomes why DHS invested in a layered stack rather than a single rule. The clearest answer to that question comes down to the sheer scope of the department. DHS runs 15 operating components, protects 16 critical infrastructure sectors, and operates at airports, borders, maritime ports, cyber networks, disaster zones, and inside the Secret Service threat triage pipeline. One rule could not have covered all of that work credibly, and that mix is why the federal AI rules look modular rather than monolithic. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

The second driver was the pace at which generative AI entered agency workflows after late 2022. Front-line officers began using commercial chatbots for drafting narratives, triaging tips, and summarizing case files without clear policies. DHS leadership documented more than 160 AI uses across components, with a disproportionate share tied to AI in law enforcement and immigration adjudication. The DHS AI rules emerged to give those teams a shared vocabulary and a safety checklist. The rules also created an escalation path that did not depend on any single vendor or administration.

The Core Pillars of the DHS AI Rules Framework

Shifting focus to the DHS AI rules framework, the April 2024 document is the backbone of the DHS AI rules for critical infrastructure. It applies the shared vocabulary of risk roles that the framework calls cloud and compute providers, AI developers, critical infrastructure owners and operators, civil society, and the public sector. Each role carries a set of concrete responsibilities, not aspirations, and the framework asks each party to assume adjacent responsibilities too. This role-based structure is why the framework survived the change of administrations with only minor edits. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

The five pillars translate neatly into a readiness scorecard for any infrastructure operator. Cloud providers must document physical and logical safeguards for AI compute, support secure model handling, and offer customer-facing abuse reporting. AI developers must evaluate pre-deployment risks, maintain model cards, provide red-team access, and publish security disclosures. Owners and operators must inventory AI dependencies, align AI procurement to risk, train staff, and route critical decisions through human review. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

Civil society and the public sector share the final two pillars in the DHS AI direction. Civil society partners are expected to run independent audits, publish findings, and feed those findings back to CISA and the sector risk management agencies. Public-sector entities including DHS itself must coordinate research funding, convene stakeholders through forums like the AI Safety and Security Board, and update the framework as attack surfaces shift. The original framework document runs 48 pages and includes checklists for each pillar. Together these pillars draw a line from research funding to boardroom accountability for every AI system that touches a critical sector.

The pillars matter because they resolve a long-running argument about who owns AI risk in a shared supply chain. Before the framework, cloud providers blamed model vendors, model vendors blamed deployers, and deployers blamed data suppliers for failures that often had multiple causes. the guidelines force each party to accept a floor of responsibility that neighbours can audit against. That alignment is the single most useful artifact in the DHS guidance for a security leader building a program. It is also frequently cited in procurement contracts across sectors today.

How the DHS AI Rules Roadmap Fits With the Framework

Beyond the framework, the DHS AI Roadmap sets internal priorities for the agency itself. The roadmap identifies three focus lines of effort: using AI to combat the fentanyl supply chain and transnational criminal organizations, strengthening disaster response and recovery, and modernizing immigration case processing. It also commits to publishing updated use-case inventories, hiring an AI corps of 50 technologists, and running departmental pilots including a border intelligence RAG system. The roadmap is where mission intent lives inside the framework stack. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

Private-sector operators often skip the roadmap on the belief that it does not apply to them. That reading undersells how roadmap priorities shape procurement, grant funding, and sector-specific partnerships. A roadmap signal that disaster response is a priority creates downstream contract opportunities for commercial geospatial AI vendors. A roadmap signal on cyber defense feeds the CISA AI Roadmap on managing risk and shapes which pilot programs survive. the DHS framework therefore reach vendors indirectly through where DHS chooses to spend. Reading the roadmap tells you which doors will open and when.

The 2025 GenAI Playbook for Public Sector Deployment

Turning to the GenAI Playbook, DHS released this operational manual on 7 January 2025 as a practical companion to the framework and the roadmap. The playbook walks a public-sector team through a 20-plus-step adoption lifecycle, from mission scoping and vendor selection to monitoring and sunset. It covers both proprietary and open-source generative AI, which is unusual among federal guidance documents. The playbook also includes evaluation templates, procurement clauses, and a human-in-the-loop decision tree. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

Three sections of the playbook stand out for private operators studying the DHS guidance. First, the use-case scoping worksheet asks whether a mission could be accomplished without generative AI, which filters out projects that would fail later. Second, the risk-tier mapping sorts tools into low, moderate, and high impact categories, closely mirroring the EU AI Act’s risk tiering. Third, the operations section defines what logging, access control, and incident reporting look like for a running generative tool. The DHS press release for the GenAI Playbook links to the full PDF, which is roughly 70 pages.

The playbook also integrates with wider sector guidance including CISA’s secure AI development guidelines. For teams that already use the responsible AI governance frameworks from NIST, the playbook maps cleanly onto the Govern, Map, Measure, and Manage functions. the DHS stack therefore do not duplicate NIST, they operationalize it for public-sector workloads. That is why federal agencies often treat the playbook as the first thing a new AI product owner reads on day one. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

What Changed Under the 2026 Executive Order on AI

Looking at the 2026 executive order, the policy picture shifted in June when President Trump signed the Executive Order on Promoting Advanced Artificial Intelligence Innovation and Security. The order replaced the Biden-era EO 14110 and reset federal AI priorities around speed, model exportability, red-teaming, and reduced regulatory friction. It retained the Safety and Security Framework intact, including the five pillars, and reaffirmed CISA’s role in co-authoring guidance for secure AI development. For critical infrastructure operators the practical effect was limited because the framework pillars survived. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

The order also made three concrete changes that practitioners should track inside the DHS AI policy. First, it rolled back the pre-deployment compute reporting thresholds for commercial frontier models while keeping classified reporting for defense use. Second, it directed OMB to accelerate agency AI procurements and clarified that pilots can run without the longer impact assessments the Biden rule required. Third, it reinforced the AI Safety and Security Board at DHS, which continues to convene industry leaders and civil society in a quarterly cadence. For a deeper tour of the order’s language, see the Mayer Brown analysis of the 2026 AI EO.

Who the DHS AI Rules Apply To

Stepping back from the policy history, the DHS AI rules apply to a wider audience than the title suggests. Federal civilian agencies must comply with OMB memos M-24-10 and successor guidance, which operationalize the framework’s principles across the executive branch. The 16 critical infrastructure sectors face expectations through sector risk management agencies, with electricity, water, transportation, and communications leading early adoption. State and local law enforcement agencies that receive DHS grants face procurement clauses tied to the framework. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

Private-sector vendors are the fastest-growing audience for the federal AI guidance in practice. Companies selling AI to any DHS component must now adopt framework language in contracts, deliverables, and incident response procedures. That includes the big cloud providers, model developers like Anthropic and OpenAI, and systems integrators building classified or law-enforcement workloads. Smaller vendors face a lighter burden through subcontracting clauses that flow down the primary obligations. See AI governance trends and regulations for how similar flow-downs appear in state frameworks today.

Civil society organizations are the final audience even though they are not regulated by the Safety and Security Framework. The framework explicitly asks academic researchers, independent auditors, and advocacy groups to publish findings on operator AI deployments. Those findings feed back into CISA and the sector risk management agencies through structured public comment windows. The DHS AI responsibility page keeps a running list of partner organizations and ongoing audits. The practical reach of the DHS AI policy is therefore wider than any one document would suggest.

AI Across the DHS Mission: Border, Cyber, FEMA, Secret Service

Turning to how the DHS AI rules shape mission work, the agency now runs AI inside nearly every operating component. Customs and Border Protection uses machine vision at ports of entry, analytic triage inside the Automated Targeting System, and biometric matching through the Traveler Verification Service. The United States Coast Guard deploys computer vision on cutters and aircraft for search and rescue. Immigration and Customs Enforcement runs AI inside case triage, and USCIS uses natural language processing to accelerate asylum interview summaries. These uses are documented in the public use-case inventory and are governed by the framework pillars.

CISA’s AI mission is the most visible slice of the guidelines for cyber defenders. The agency co-authored the joint CISA and UK NCSC Guidelines for Secure AI System Development, which 23 international partners have endorsed. CISA also runs AI red-team exercises against government workloads and publishes advisories for commercial AI products with disclosed vulnerabilities. These exercises are the operational face of the framework’s AI developer pillar. the framework stack reach commercial AI vendors through CISA because that is where secure-by-design meets real-world threat intelligence.

FEMA is the quieter but faster-growing adopter of AI inside DHS. The agency uses satellite and drone imagery for post-disaster damage assessment, cutting turnaround time from weeks to days after hurricanes and wildfires. FEMA’s AI tools also triage citizen aid applications, which historically produced long queues after major events. The framework pillars show up here too, through model documentation, human review of denial decisions, and bias audits aligned with the AI and data redefining surveillance security playbook. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

The Secret Service rounds out the big-four AI missions inside DHS. The Service’s National Threat Assessment Center uses natural language models to triage threatening communications toward public figures and schools. The AI output always flows through human analysts before an operational decision is made. That human-in-the-loop requirement is a direct implementation of the framework’s human-review pillar and is one of the most visible applications of the DHS AI policy across the full department. Each mission also shows how the stack combines pillars and playbook procedures to produce decisions that an inspector general can audit.

Civil Liberties, Bias, Ethics, and Due Process Guardrails

Shifting focus to civil liberties, the DHS framework include three structural guardrails that are easy to miss. The Office for Civil Rights and Civil Liberties runs an impact assessment program that reviews every new AI system before deployment. The Privacy Office requires a Privacy Impact Assessment and a System of Records Notice before any model touches personally identifiable information. The Office of the Chief Information Officer maintains the use-case inventory and flags systems that risk disparate outcomes along protected characteristics. These three offices form a tripartite internal review before any external compliance ever happens.

The guardrails face real criticism and the DHS AI rules do not resolve every concern. The American Immigration Council has argued that AI in immigration adjudication risks encoding past bias and lacks adequate due-process rights for applicants. Georgetown’s Center on Privacy and Technology has pointed to facial recognition deployments at airports that still show measurable error gaps by skin tone. Advocacy groups have asked for a formal right to AI appeal with human review attached to every life-affecting decision. These critiques will likely shape future updates to the framework rather than disappear quietly.

Operators who want to go beyond the DHS AI direction can adopt three practices that civil society groups recommend. First, publish model cards and bias evaluations for every production system that affects people, not just internal pilots. Second, offer a plain-language appeal channel that routes to a human reviewer with authority to overturn the AI output. Third, align internal reviews with the AI impact on privacy and AI privacy concerns literature that advocacy groups publish quarterly. These three practices turn a compliance exercise into a trust exercise and strengthen the federal AI rules in practice.

Guidance for Critical Infrastructure Owners and Operators

Beyond federal agencies, the DHS AI policy speak most directly to critical infrastructure owners and operators. The framework asks operators to maintain an AI inventory, perform risk-tiered assessments, and route high-impact decisions through human review. Operators must also train staff on AI capabilities and limitations and must report AI incidents to CISA through established channels. These obligations are voluntary in text and increasingly expected in sector guidance and insurance underwriting. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

Water, power, communications, and transportation are the sectors moving fastest. Water utilities have adopted AI for leak detection, consumption anomaly scoring, and predictive maintenance of pumps and treatment systems. Electric utilities use AI for wildfire ignition risk, load forecasting, and insider threat triage. Communications providers now scan for AI-generated voice phishing and deepfake impersonation at scale. Transportation operators including airports and railroads use AI for computer-vision perimeter monitoring and intrusion detection, with AI incident reporting running through AI and cybersecurity partnerships.

Red Teaming, Model Documentation, and Technical Safeguards

Turning to technical safeguards, the DHS AI direction ask AI developers to adopt four concrete practices. The first is systematic pre-deployment red-teaming of frontier models against misuse, prompt injection, and model exfiltration. The second is model documentation through published model cards covering training data, known failure modes, and recommended use cases. The third is a secure development lifecycle that mirrors the CISA Secure by Design pledge, including coordinated vulnerability disclosure. The fourth is incident reporting through CISA’s AI incident channel when a production system produces harmful output at scale.

Red teaming is where the guidelines diverge most clearly from older cybersecurity practice. AI red teaming is less about network penetration and more about adversarial prompts, jailbreak chains, synthetic persona attacks, and dataset poisoning. The 2026 executive order explicitly preserved red-team obligations for frontier models in regulated sectors and increased the role of DHS in standardizing those exercises. Vendors including Anthropic, OpenAI, and Google now publish periodic red-team reports in partnership with CISA. The practical effect is that red teaming is now a procurement criterion, not just a hygiene step.

Model documentation is the second place where the DHS guidance create daily operational work. Model cards must now cover intended use, prohibited use, performance across demographic slices, data provenance, update cadence, and incident contact information. A missing model card can delay a procurement cycle or trigger inspector general scrutiny after a public incident. Operators often align model cards with the broader managing AI-related risks approach the private sector already follows. the framework therefore turn documentation into an auditable artifact, not a nice-to-have.

How the DHS Guidelines Interact With NIST AI RMF and the EU AI Act

Looking across the regulatory map, the DHS AI rules do not stand alone. The NIST AI Risk Management Framework covers Govern, Map, Measure, and Manage functions that align with the framework’s role pillars. The EU AI Act takes a risk-tiered approach that mirrors the GenAI Playbook’s low, moderate, and high categorization. Operators often map their internal AI inventory once and then produce three overlapping compliance views. This triple-mapping reduces redundant work and keeps multinational operators out of parallel bureaucracies.

The three regimes diverge on enforcement style and on definitions of high risk. The DHS framework is voluntary for private operators and nudges through procurement, grants, and sector guidance. NIST AI RMF is voluntary in form but increasingly cited in federal rulemakings, insurance contracts, and state laws like the Colorado AI Act compliance model. The EU AI Act is prescriptive, with heavy penalties for high-risk and prohibited uses that come into force on a staggered timeline through 2027. Vendors selling across the Atlantic now treat the EU rules as the compliance floor.

For a multinational critical-infrastructure operator, mapping all three regimes is the pragmatic path. the DHS framework align with NIST on language and with the EU on risk tiering, so a single inventory can satisfy all three with modest tailoring. The CISA secure development guidance also aligns with the UK NCSC equivalent, which means a London-based operator and a Houston-based operator can share a model card template. Operators who struggle with this mapping often adopt a shared taxonomy from the broader AI governance trends and regulations literature. The DHS guidance, read with NIST and the EU AI Act, create a workable global baseline.

Procurement, Vendor Contracts, and AI Supply Chain Rules

Shifting focus to procurement, the DHS stack reach vendors most powerfully through contract language. DHS procurement officers now insert standard clauses on model documentation, red-team results, data provenance, and incident reporting into AI-related solicitations. The clauses flow down to subcontractors, which means a small AI startup selling into a prime integrator must still meet the framework’s floor. Procurement is where soft guidance becomes hard contract, and it is why so many vendors have invested in model cards and red-team reports over the past 18 months. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

Supply chain visibility is the second procurement focus of the DHS AI policy. Operators must now understand which base models their vendors use, which training data flows through those models, and which guardrails ship by default. That visibility is harder than it sounds because AI stacks are often multi-vendor by design. The DHS AI rules borrow from Software Bill of Materials practice and extend it with an AI Bill of Materials concept covering models, datasets, prompts, and evaluation suites. See deterministic guardrails for AI agents for how operators enforce these clauses in deployed systems.

DHS AI Use Case Inventory: What the Numbers Reveal

Beyond the policy text, the DHS AI use-case inventory offers the clearest picture of agency AI practice. The December 2024 refresh listed 158 use cases across 15 operating components, up from 42 cases in 2023. Law enforcement is the leading mission category, followed by cybersecurity, workforce enablement, and benefits adjudication. The inventory is updated annually and is one of the most transparent federal AI disclosures in the world. Policymakers, researchers, and operators treat it as a baseline for AI adoption measurement.

Three patterns in the inventory tell operators where the federal AI guidance will tighten next. First, generative AI use cases grew faster than classical machine learning, which means playbook requirements will apply to more systems over time. Second, high-impact use cases that affect life, liberty, or livelihood represent a disproportionate share of inspector general scrutiny. Third, systems that touch personally identifiable information are the most likely to carry both a Privacy Impact Assessment and a System of Records Notice, which signals extra documentation burden. Operators building similar systems in the private sector can anticipate the same scrutiny.

The inventory also discloses which AI systems have been retired because of underperformance or civil liberties concerns. Retired systems include tools that generated unacceptable false positive rates in triage or produced disparate outcomes along demographic lines. Transparent retirement is as important as transparent deployment, and the Safety and Security Framework explicitly encourage both. For a tour of the inventory and its implications, see the DHS deep dive on the AI use-case inventory, which breaks down categories, risk tiers, and sunset decisions. Operators who adopt early find the rule set continues to evolve with sector input across many quarters.

Workforce AI literacy is the final signal the inventory sends. DHS now trains more than 50,000 staff on AI use, limitations, and reporting procedures, and that number continues to grow with the AI corps hiring effort. Workforce enablement is a quiet but durable element of the DHS AI policy because many AI failures start with user misuse rather than model failure. Operators adopting the framework often underweight this training layer and later discover that the easiest wins come from upskilling, not from new tooling. The latest inventory shows that DHS has clearly internalized the workforce-training lesson across its many operating components.

Risks That the DHS Guidelines Are Trying to Prevent

Turning to the risk landscape, the guidelines target a specific set of failure modes. The highest-priority risks are AI-enabled cyber attacks on critical infrastructure sectors across the country. Second is AI misuse in producing chemical, biological, radiological, or nuclear threats of various kinds. Third is the disruption of public services from unexpected AI model failures. These three families drive most of the framework’s technical requirements, including red-teaming, incident reporting, and secure development. The GenAI Playbook adds a fourth category covering trust and transparency failures that erode public confidence.

Second-tier risks still matter and shape operator-level decisions in meaningful ways across many infrastructure sectors. Deepfake-driven social engineering now targets executives at utilities, carriers, and transportation operators with impersonation attempts that bypass voice verification. See cybersecurity leaders tackle generative AI threats for how CISOs are responding. Insider threat is another second-tier risk, with privileged users leaking training data or model weights by accident or by design. the framework stack treat insiders as a developer-pillar and operator-pillar concern simultaneously, which forces joint accountability.

Third-tier risks are easy to dismiss but surface quickly in production. AI output quality drift, concept drift from changing input distributions, and hallucination in generative tools can produce silent failures that erode trust before an incident is declared. The DHS AI policy ask operators to monitor these risks through logging, continuous evaluation, and user feedback channels. Many operators find that the operations section of the GenAI Playbook captures these practices well. Collectively the risk list is why the framework exists, and tracking those risks is the measurement work that proves the DHS framework are doing their job.

Operational Rollout of the DHS AI Rules in Your Organization

Looking at implementation, the DHS AI rules translate into a sequenced 90-day program for most operators. Days 1 through 30 are spent on inventory, mapping every AI touchpoint across the organization, including third-party models bundled into SaaS products. Days 31 through 60 cover risk tiering, assigning each use case to a low, moderate, or high impact category and defining required controls per tier. Days 61 through 90 cover governance, standing up an AI review board, publishing model cards for production systems, and establishing an incident reporting channel into CISA. The sequence mirrors how DHS itself phased adoption of AI programs across its various operating components.

Three common implementation traps catch operators who skip the sequence and try to shortcut their rollout. The first trap is procuring AI tools before publishing an inventory, which leads to shadow AI and compliance gaps. The second is treating red-teaming as a one-time event rather than a continuous process tied to model updates. The third is underinvesting in workforce training, which creates misuse incidents that look like model failures. Each trap can be avoided by sticking to the 90-day sequence and by treating the DHS AI direction as a living program rather than a one-off project.

Governance decisions are the hardest part of the DHS AI rules to translate into practice. The framework recommends a cross-functional AI review board that includes security, privacy, legal, product, operations, and executive sponsors. Boards work best with a 30-minute weekly cadence rather than a quarterly rhythm because AI change velocity is high. They also need a documented escalation path to the executive sponsor and the board for high-impact decisions. Operators who copy DHS governance patterns tend to see faster adoption of the federal AI rules across business units.

Measurement is the final implementation discipline, and it determines whether a program survives tight budget cycles. The DHS AI policy emphasize measurable outcomes including incident rates, user feedback scores, and model performance by demographic slice. Operators who build dashboards early create a feedback loop that keeps programs funded during tight budget cycles. See autonomous AI agents and oversight for how measurement tooling is evolving. A program with dashboards tends to survive leadership changes because the numbers travel faster than the people. That durability is itself an argument for taking the DHS AI direction seriously now.

The Future of the guidelines Through 2030

Looking ahead, the DHS guidance are set to deepen in three directions through 2030. The first is tighter alignment with the NIST AI RMF Generative AI Profile and the EU AI Act’s General-Purpose AI Model obligations. The second is more granular sector-specific annexes for electricity, water, communications, and transportation, each with named controls and reporting cadences. The third is a formal AI vendor certification program that would turn the voluntary framework into a certification floor for critical-infrastructure procurements. Each of these directions is already visible inside the DHS working groups and quarterly stakeholder forums.

Watch three concrete milestones over the next 24 months to gauge the trajectory of the framework. First, the 2026 use-case inventory refresh will show whether DHS is still growing AI adoption or consolidating. Second, the next CISA secure AI development update will reveal which technical safeguards have gone from voluntary to expected. Third, the forthcoming sector-specific annexes will show whether sector risk management agencies have moved from guidance to measurable requirements. Each milestone will reshape how operators plan budgets and training.

The deeper arc of these federal rules is actually simpler than the layered documentation suggests on its surface. the DHS framework started as a response to one 2023 executive order and have evolved into a shared federal baseline that outlived administrations. The pillars survived the 2026 EO reset because they describe how AI risk actually distributes along a supply chain. Operators who adopt the DHS guidance are therefore not betting on any one administration or any one technology vendor. They are investing in a durable governance pattern that the next decade will almost certainly extend further.

DHS AI Use Case Inventory, 2024

Where DHS Uses AI the Most

Approximate share of DHS production AI systems by mission category, from the December 2024 use-case inventory covering roughly 158 systems across 15 components.

0%20%40%

Source: DHS 2024 AI Use Case Inventory (approx. 158 systems), reported shares rounded. Full inventory at dhs.gov.

Key Insights on the DHS stack

  • The December 2024 DHS use-case inventory listed about 158 production AI systems across 15 operating components. Law enforcement represented the leading mission category by share of listed systems in that calendar year.
  • CISA and the UK NCSC coordinated the joint secure AI development guidelines that 23 international partners signed on. The alignment reduces duplicate audit burden for multinational vendors operating across many different global jurisdictions today.
  • The April 2024 DHS Safety and Security Framework runs 48 pages across five role-based pillars for operators. Each pillar carries a checklist that infrastructure operators can map onto their existing control sets.
  • The January 2025 DHS GenAI Playbook includes a comprehensive 20-step adoption lifecycle for public-sector teams. The lifecycle mirrors how enterprise product teams already govern software from early scoping to final retirement.
  • The June 2026 Executive Order on Advanced AI Innovation replaced the earlier Biden-era order on federal AI. It kept the framework pillars intact and loosened some reporting rules for commercial frontier model developers.
  • DHS has committed to hiring an AI corps of 50 specialist technologists across its operating components. The department now trains more than 50,000 staff on AI use, limitations, and incident reporting procedures.
  • Civil liberties scrutiny of the DHS AI rules is concentrated in immigration adjudication processes today. The American Immigration Council warning on AI in immigration decisions is now shaping draft framework updates.

Taken together, the signals around the federal AI guidance point to a stable federal baseline that will deepen rather than reset. The pillars survived a change in administration, which suggests the role-based model has broad bipartisan support. Procurement language is doing more work than press releases, and that is where vendors feel the daily pressure. Civil liberties critiques are driving the next generation of annexes and will likely sharpen rather than fade. the Safety and Security Framework are therefore moving from policy document to operational norm, and operators who adopt them early will have the lightest compliance lift in 2027.

DHS AI Guidelines Compared: Framework, Roadmap, Playbook

The comparison below sorts the four DHS AI Guidelines instruments by audience, enforcement, and transparency dimensions. Operators can use the table to map their program against the right rulebook. Each column of the table traces one of the four federal AI governance instruments individually. The rows cover the dimensions that practitioners most often ask about during audits and procurement reviews. Reading across the row shows how guidance deepens from principles into contract language. The columns stay in release-date order from April 2024 to June 2026.

DimensionSafety and Security Framework (April 2024)DHS AI Roadmap (March 2024)GenAI Playbook (January 2025)2026 AI Executive Order
Primary audienceCritical infrastructure owners and the full AI supply chainDHS components internallyPublic-sector teams adopting generative AIAll federal agencies and vendors
Enforcement mechanismVoluntary with procurement flow-downInternal priorities and budget allocationOMB and agency CIO oversightExecutive order with OMB guidance
Scope of transparencyRole pillars, no public reporting mandateUse-case inventory and roadmap updatesModel documentation and risk tieringFrontier model reporting adjusted
Public participationCivil society as a formal pillarStakeholder forums quarterlyPublic comment on playbook refreshAI Safety and Security Board role retained
Decision-making roleRisk-tiered human-in-the-loopMission priorities and budgetPilot approval and sunset decisionsProcurement acceleration
Misinformation postureDeepfake and voice-cloning threat languageElection integrity referencesContent provenance toolsAI content labeling preserved
Service delivery stancePublic safety and incident reportingFaster disaster response and triagePublic-sector productivity gainsIndustrial base and export posture
Accountability laneRole-based across supply chainDHS component ownersAgency CIO plus review boardsWhite House and OMB oversight

Real-World Examples of DHS AI Guidelines in Action

Three agency examples show the DHS AI Guidelines applied in production with measurable outcomes and documented limitations. The examples cover border security, disaster response, and threat triage. Each example cites agency reporting and civil society critique together. Readers can trace the framework pillars from text into concrete operational metrics in real agency programs today. The examples pair with case studies later in the article.

CBP’s Automated Targeting System and Travel Facilitation

Customs and Border Protection has deployed the Automated Targeting System and adopted machine-learning risk scoring for cargo and travelers. The system handles more than 200 million annual cargo entries and roughly 400 million annual passenger processing events across all ports. The system has flagged narcotics seizures, high-risk cargo containers, and inadmissible travelers through tiered risk scoring aligned with the framework human-in-the-loop pillar. CBP reported that AI-assisted targeting produced a 42 percent increase in fentanyl seizures and reduced response hours per screening lane in fiscal year 2024. The system still faces criticism for opacity around individual risk scores and for limited public auditability of error rates in regional reporting according to the 2024 DHS use-cases report. The DHS AI rules directly shape current reforms including published model performance by border region and expanded Office for Civil Rights and Civil Liberties oversight. The example shows how pillar language turns into operational metrics inside a flagship mission system over multiple years of use.

FEMA Damage Assessment After Hurricane Helene

FEMA deployed AI-driven satellite and drone imagery analysis after Hurricane Helene in September 2024. The deployment cut post-disaster damage assessment time from an average of 14 days to roughly 3 days across affected counties. The AI combined computer vision with structured hazard models to prioritize search-and-rescue resources and triage individual assistance applications. The disaster response and risk management capability now routes human reviewers to high-confidence loss cases first, reducing wait times for displaced families. FEMA still faces criticism around model performance in rural areas with limited reference imagery and around transparency of denial reasoning. The DHS AI policy required bias audits before the rollout, and FEMA has committed to publishing performance by county starting in 2026. The example illustrates how the framework scales from policy to lifesaving operational speed.

United States Secret Service Threat Triage With NLP Models

The United States Secret Service’s National Threat Assessment Center has deployed natural language models to triage inbound threat communications targeting public figures, elected officials, and schools. The models prioritize review queues so that analysts handle the highest-urgency communications within hours instead of days. The Service reported in 2024 that AI-assisted triage increased reviewer throughput by roughly 40 percent while maintaining human-final authority on every operational decision per the DHS AI guidelines. The system draws criticism from AI impact on privacy literature over the collection and retention of flagged communications and the risk of false positives on protected speech. The Service responded with narrower retention windows and quarterly civil liberties audits, which are now template practices across DHS. The example shows pillar-based accountability working in a sensitive national security mission.

Recommended reading

Books to Go Deeper on AI Policy and Deployment

Two books that pair well with the DHS framework for operators building programs this year.

The AI Playbook: Mastering the Rare Art of Machine Learning Deployment

The AI Playbook: Mastering the Rare Art of Machine Learning Deployment

Practical ML and AI deployment handbook that directly supports the operator-pillar practices the DHS AI rules expect for critical infrastructure.

Buy on Amazon
The Age of AI: And Our Human Future

The Age of AI: And Our Human Future

Policy and national-security framing of AI from Kissinger, Schmidt, and Huttenlocher, essential context for the DHS AI direction audience.

Buy on Amazon

As an Amazon Associate, AIplusInfo earns from qualifying purchases.

Case Studies of Agency and Industry Adoption

Three deeper case studies show how operators and agencies translated the DHS AI guidelines into measurable change. Each case study names the problem, the solution path, measurable impact, and residual limitations. The cases cover water utility operations, airport facial recognition, and federal asylum adjudication processing today. Readers can see how the five framework pillars translate into board-level decisions and daily operational choices. The three cases below pair with the shorter real-world examples section earlier in this article.

Case Study: Water Sector Adoption of the AI Framework

A regional water utility serving roughly 1.2 million customers faced an aging distribution network losing an estimated 18 percent of pumped water annually to leaks and metering errors. The utility adopted the DHS AI rules owner-operator pillar as its template. The team published a model card for its AI leak-detection system. All high-confidence alerts route through a human dispatch review step before action. Within 11 months of adoption the utility cut non-revenue water losses to 11 percent across its service area. The move saved an estimated USD 7.4 million annually and improved pump uptime significantly. It also freed hundreds of crew hours for new predictive maintenance programs.

The utility also stood up an incident reporting channel into CISA, which triggered a shared threat advisory with three peer utilities during a model-poisoning attempt in 2025. The DHS critical infrastructure framework rollout remains the template referenced in sector board meetings and procurement cycles. The utility still faces criticism from local community groups over data retention policies on residential consumption patterns. The pressure has pushed its board to adopt tighter minimization rules than the framework requires. The case study demonstrates how a framework pillar becomes a measurable improvement in both uptime and public trust.

Case Study: Airport Facial Recognition and Civil Rights Audit

A major United States airport authority faced the challenge of processing surges of travelers at peak times. The authority deployed CBP’s Traveler Verification Service across international arrivals in 2024. The system processed roughly 23 million travelers with reported match rates above 99 percent for enrolled travelers. Civil society audits identified error gaps affecting Black and Asian travelers at rates two to five times higher than white travelers, consistent with academic findings. The federal AI rules required an Office for Civil Rights and Civil Liberties review of the deployment. The review led the airport authority to add an opt-out lane and publish a bias dashboard. Officers were also retrained on alternative verification procedures for travelers who declined matching.

The retraining produced a measurable 42 percent reduction in secondary inspections for travelers who opted out of facial matching. The reduction addressed a key civil liberties concern raised during the 2024 DHS facial recognition review. The airport also joined a sector working group that now publishes a shared metric suite covering accuracy, equity, and traveler experience. The system still faces criticism from facial recognition debate organizations over long-term data retention and over the real-world voluntariness of airport opt-out procedures. The case study illustrates how the DHS AI policy turn critique into measurable change without halting operations.

Case Study: USCIS AI-Assisted Asylum Interview Summaries

United States Citizenship and Immigration Services faced the challenge of long documentation times after asylum officer interviews. The agency piloted an AI solution to summarize those interviews across three field offices. The pilot aimed to cut post-interview documentation time that averaged 90 minutes per case. The pilot covered roughly 11,000 cases across three field offices during fiscal year 2024 and cut documentation time to an average of 32 minutes per case. The savings freed officers to run deeper credibility assessments on each applicant. The pilot reduced case backlog growth in the pilot offices by an estimated 18 percent over nine months. These results were reported in the DHS AI playbook rollout coverage.

The pilot ran under the DHS AI rules playbook with risk-tier classification as moderate. A full human-in-the-loop review covered every summary before any final use in casework. The team also published a model card describing training data and failure modes. Civil liberties advocates still criticized the pilot over the risk of flattening linguistic nuance in summaries. The risk is critical to asylum credibility judgments and draws on the Invisible Gatekeepers research on AI in immigration adjudication. USCIS added a mandatory nuance-flagging prompt and extended the review requirement to high-stakes decisions in response. The case study shows how the DHS AI guidelines allow pilots to proceed while keeping civil liberties review in the loop.

Frequently Asked Questions About the DHS AI Rules

What are the DHS guidance?

The DHS AI rules are a layered federal governance stack across agencies. They combine the April 2024 Safety and Security Framework, the March 2024 DHS AI Roadmap, the January 2025 GenAI Playbook, and the June 2026 Executive Order. Together they define role-based responsibilities, mission priorities, adoption lifecycles, and procurement expectations.

Are the DHS AI policy mandatory for private companies?

The Safety and Security Framework is voluntary in text for private critical infrastructure operators. Compliance is pushed through procurement contracts, sector guidance, and insurance underwriting. Vendors selling to any DHS component must now adopt framework language in their contracts and deliverables.

Who issues the DHS AI guidelines?

The Department of Homeland Security issues the Safety and Security Framework, the AI Roadmap, and the GenAI Playbook. CISA co-publishes technical guidance with the UK NCSC and 23 international partners. The White House and OMB layer executive-order direction and agency memos on top of the DHS-authored documents.

What are the five pillars of the DHS AI framework?

The five pillars assign responsibilities to cloud and compute providers, AI developers, critical infrastructure owners and operators, civil society, and the public sector. Each pillar carries a detailed checklist of concrete practices and expected outputs. The pillars are designed so that neighboring roles can audit against each other across the AI supply chain.

How did the 2026 Executive Order change the DHS AI rules?

The 2026 Executive Order replaced EO 14110 and reset federal AI priorities around speed, exportability, and red teaming. The Safety and Security Framework pillars survived the policy transition entirely intact and unmodified. Compute-threshold reporting loosened for commercial frontier models, and OMB accelerated agency AI procurement timelines.

How do the DHS AI guidelines compare to the EU AI Act?

The DHS framework is voluntary for private operators and uses a risk-role-based structure for responsibilities. The EU AI Act is prescriptive and risk-tier-based with heavy penalties for high-risk and prohibited uses. The two regimes align on risk categorization and documentation but diverge on enforcement style. Multinational operators map once and produce three overlapping compliance views.

What is in the DHS GenAI Playbook?

The January 2025 GenAI Playbook is a 20-plus-step adoption lifecycle for public-sector generative AI. It covers mission scoping, vendor selection, risk tiering, procurement clauses, operations, logging, incident response, and secure sunset. It integrates with CISA secure development guidance and maps cleanly onto the NIST AI RMF functions.

Does DHS use facial recognition under the AI guidelines?

Yes, DHS components use facial recognition for traveler verification at ports of entry and in some investigative contexts. The DHS AI guidelines require bias audits, model documentation, and human review for high-impact decisions. Civil society critics continue to flag demographic error gaps and retention policies as unresolved concerns.

How many AI systems does DHS operate?

The December 2024 use-case inventory listed roughly 158 production AI systems across 15 DHS components. Law enforcement is the leading mission category, with cybersecurity, workforce enablement, and benefits adjudication close behind. Generative AI systems grew fastest year over year inside that inventory.

What is CISA’s role in the DHS AI guidelines?

CISA leads cyber-focused AI guidance across the federal AI guidance stack. The agency co-authored the Guidelines for Secure AI System Development with the UK NCSC and 23 international partners. CISA also runs red-team exercises, publishes vulnerability advisories, and receives AI incident reports from critical infrastructure operators.

How does an operator start implementing the Safety and Security Framework?

Operators typically start with a 90-day implementation sequence running across inventory, risk tiering, and governance. Days 1 to 30 produce an AI inventory across all departments. Days 31 to 60 cover risk tiering with low, moderate, and high impact categories. Days 61 to 90 stand up governance, publish model cards, and establish an incident reporting channel into CISA.

Do the DHS AI guidelines require model cards?

Model cards are a core expectation under the framework and the GenAI Playbook. They must document intended use, prohibited use, training data provenance, performance across demographic slices, and update cadence. Missing or outdated model cards can delay procurement cycles and trigger inspector general scrutiny after public incidents.

How are civil liberties protected under the DHS AI policy?

The Office for Civil Rights and Civil Liberties, the Privacy Office, and the Office of the Chief Information Officer each review AI systems before deployment. They run impact assessments, Privacy Impact Assessments, and inventory classification. Advocacy groups still press for stronger appeal rights and transparency on individual-level AI decisions.

What risks are the guidelines trying to prevent?

The top-tier risks include AI-enabled cyber attacks on critical infrastructure sectors across the country. The rules also target misuse of AI in chemical, biological, radiological, or nuclear threats of various kinds. Large-scale AI failures that disrupt public services across utilities are a third major concern. The guidelines also address deepfake social engineering, insider misuse, and silent model drift in production systems.

Will the framework stack become mandatory in the future?

Observers expect sector-specific annexes to add measurable requirements for electricity, water, communications, and transportation. A formal AI vendor certification program is under discussion inside DHS working groups. Procurement flow-down and insurance underwriting are already turning voluntary guidance into effective requirements for most operators.